#appsec — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #appsec, aggregated by home.social.
-
Security Tip: Don’t ignore transitive dependencies. 🛡️ Modern apps rely on hundreds of third-party libraries. While you might track your direct imports, vulnerabilities often lurk in the dependencies of dependencies. Manual tracking is impossible. Use Software Composition Analysis (SCA) tools to map your full dependency tree and alert on known CVEs. Stay informed on the latest vulnerabilities: https://cvedatabase.com #CVE #InfoSec #CyberSecurity #AppSec #DevSecOps
-
🌐 WEB SECURITY TESTING ROADMAP
From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.
⚡ Learn the process. Test responsibly. Build secure.
-
🌐 WEB SECURITY TESTING ROADMAP
From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.
⚡ Learn the process. Test responsibly. Build secure.
-
I wanted to see what a secure build-time Java patch looks like after the annotation.
The example uses a fictional access-policy SDK. Quarkus Shim replaces one method during the build. The pipeline proves the old and new behavior, keeps the dependency in the SBOM, stores the bytecode dump, and rejects an expired patch.
https://www.the-main-thread.com/p/quarkus-shim-secure-java-pipeline
-
I wanted to see what a secure build-time Java patch looks like after the annotation.
The example uses a fictional access-policy SDK. Quarkus Shim replaces one method during the build. The pipeline proves the old and new behavior, keeps the dependency in the SBOM, stores the bytecode dump, and rejects an expired patch.
https://www.the-main-thread.com/p/quarkus-shim-secure-java-pipeline
-
Prompt injection is still king, but “excessive agency” just jumped to #3 in OWASP’s Top 10 for LLM apps. Stop chasing unbreakable models—start containing fooled agents. https://jpmellojr.blogspot.com/2026/08/owasp-top-10-for-llm-apps-2026.html #AIsecurity #OWASP #LLM #AppSec
-
Prompt injection is still king, but “excessive agency” just jumped to #3 in OWASP’s Top 10 for LLM apps. Stop chasing unbreakable models—start containing fooled agents. https://jpmellojr.blogspot.com/2026/08/owasp-top-10-for-llm-apps-2026.html #AIsecurity #OWASP #LLM #AppSec
-
Severity isn't priority. CVSS rates a flaw in isolation; ranking it needs two things no scanner sees — how exposed the component is, and what its failure costs. https://hackernoon.com/when-everything-is-critical-nothing-is #appsec
-
Severity isn't priority. CVSS rates a flaw in isolation; ranking it needs two things no scanner sees — how exposed the component is, and what its failure costs. https://hackernoon.com/when-everything-is-critical-nothing-is #appsec
-
Security Tip: Move to automated secrets rotation. 🛡️
Static credentials are a major liability. If an API key is leaked, it stays valid until someone remembers to change it. Automated rotation (using tools like HashiCorp Vault or AWS Secrets Manager) reduces the "blast radius" of a leak by ensuring credentials expire and rotate without manual intervention.
Monitor the latest threats and vulnerabilities at https://cvedatabase.com
-
It's time for another toot in our #peoplebehindosco series.
Hi @lisihocke 👋
Lisi found tech as her place to be in 2009 and has grown as a specialized generalist ever since. Building great products that deliver value together with great people motivates her and lets her thrive. As a security engineer, she’s now fully focusing on all things product security to help build more secure solutions. She’s committed to testing and quality, passionate about whole-team approaches to increase effectiveness and resilience, and enjoys experimenting and learning continuously. Having received a lot from communities, Lisi is paying it forward by sharing her stories and learning in public.
Her tags: #ProdSec, #AppSec, #DevSecOps, #SecureCoding, #SecurityTesting
She posts on Mastodon as @lisihocke and blogs at https://www.lisihocke.com.
In her free time, she plays indoor volleyball or delves into computer games and stories of all kinds.
Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.
Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.
-
It's time for another toot in our #peoplebehindosco series.
Hi @lisihocke 👋
Lisi found tech as her place to be in 2009 and has grown as a specialized generalist ever since. Building great products that deliver value together with great people motivates her and lets her thrive. As a security engineer, she’s now fully focusing on all things product security to help build more secure solutions. She’s committed to testing and quality, passionate about whole-team approaches to increase effectiveness and resilience, and enjoys experimenting and learning continuously. Having received a lot from communities, Lisi is paying it forward by sharing her stories and learning in public.
Her tags: #ProdSec, #AppSec, #DevSecOps, #SecureCoding, #SecurityTesting
She posts on Mastodon as @lisihocke and blogs at https://www.lisihocke.com.
In her free time, she plays indoor volleyball or delves into computer games and stories of all kinds.
Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.
Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.
-
How do you narrow 26,000 firmware alerts down to the 47 that actually represent product exposure? By moving from population-level data to product-specific evidence. 📊
Read this technical guide by Finite State to learn how to build a defensible remediation pipeline using binary-derived SBOMs and exploit intelligence.
Exactly the kind of practitioner-first thinking AppSec Village likes to spotlight.
Read more: https://finitestate.io/resources/how-to-prioritize-firmware-vulnerabilities-cra-compliance
-
How do you narrow 26,000 firmware alerts down to the 47 that actually represent product exposure? By moving from population-level data to product-specific evidence. 📊
Read this technical guide by Finite State to learn how to build a defensible remediation pipeline using binary-derived SBOMs and exploit intelligence.
Exactly the kind of practitioner-first thinking AppSec Village likes to spotlight.
Read more: https://finitestate.io/resources/how-to-prioritize-firmware-vulnerabilities-cra-compliance
-
A hardcoded secret. A directory traversal. A SQL injection. Individually, they're just low/medium findings. Chained together, they're a path to critical compromise.
Learn how Autonomous Attack Path Discovery finds the exploit chains traditional scanners miss.
Thank you to XBOW for supporting AppSec Village™ as our Platinum Sponsor at DEF CON 34 and throughout the year!
#AppSec #Cybersecurity #OffensiveSecurity #DevSecOps #DEFCON34
-
A hardcoded secret. A directory traversal. A SQL injection. Individually, they're just low/medium findings. Chained together, they're a path to critical compromise.
Learn how Autonomous Attack Path Discovery finds the exploit chains traditional scanners miss.
Thank you to XBOW for supporting AppSec Village™ as our Platinum Sponsor at DEF CON 34 and throughout the year!
#AppSec #Cybersecurity #OffensiveSecurity #DevSecOps #DEFCON34
-
It really does take a village. 💙
A huge thank you to our AppSec Village leadership, staff and volunteers for bringing the Village to life at #DEFCON34.
From months of planning to solving last-minute problems, welcoming attendees and keeping everything moving behind the scenes - you made it happen.
Special shoutout to our Volunteer Wrangler, Sharlene Toney, and every volunteer who gave their time and energy to the community.
We couldn’t do this without you. 🫶
-
It really does take a village. 💙
A huge thank you to our AppSec Village leadership, staff and volunteers for bringing the Village to life at #DEFCON34.
From months of planning to solving last-minute problems, welcoming attendees and keeping everything moving behind the scenes - you made it happen.
Special shoutout to our Volunteer Wrangler, Sharlene Toney, and every volunteer who gave their time and energy to the community.
We couldn’t do this without you. 🫶
-
Security Tip: Verify before you execute. 🛡️
Supply chain attacks often involve intercepting downloads to inject malicious code. Before installing new tools or libraries, always verify the artifact's integrity using provided checksums (SHA-256) or cryptographic signatures (GPG/Cosign). If the hashes don't match, don't run it.
Stay ahead of emerging threats and vulnerabilities at https://cvedatabase.com
-
CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. https://radar.offseq.com/threat/cve-2026-15534-cwe-190-integer-overflow-or-wraparound-in-leont-perl-b58a44fbf0b93abe #OffSeq #Perl #Vuln #AppSec
-
CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. https://radar.offseq.com/threat/cve-2026-15534-cwe-190-integer-overflow-or-wraparound-in-leont-perl-b58a44fbf0b93abe #OffSeq #Perl #Vuln #AppSec
-
Security Tip: Pin your dependencies with lockfiles. 🛡️ Using semantic versioning ranges (e.g., ^1.2.0) is convenient, but it introduces risk. Without a lockfile (like package-lock.json, Gemfile.lock, or requirements.txt with hashes), your CI/CD pipeline might pull a different version than what you tested locally. This "dependency drift" can introduce bugs or malicious code from a supply chain attack. Resource: https://cvedatabase.com #CVE #InfoSec #AppSec #CyberSecurity
-
What are you getting hands-on with at AppSec Village at DEF CON 34 ? 👀
Test and defend AI-powered applications, explore container escapes, build Burp extensions and Bambdas, secure the software supply chain, strengthen code-to-cloud security, or try AI-enhanced threat modeling.
Choose your workshop and reserve your spot:
https://www.appsecvillage.com/events/dc-2026 -
What are you getting hands-on with at AppSec Village at DEF CON 34 ? 👀
Test and defend AI-powered applications, explore container escapes, build Burp extensions and Bambdas, secure the software supply chain, strengthen code-to-cloud security, or try AI-enhanced threat modeling.
Choose your workshop and reserve your spot:
https://www.appsecvillage.com/events/dc-2026 -
🎉 OWASP is turning 25! 🎂
We're celebrating with a virtual party featuring awesome speakers, community stories, and more!
No travel. No hassle. Just log in, learn, connect, and celebrate 25 years of making software safer.
Join us! 🥳
https://owasp.glueup.com/event/owasp-25th-anniversary-virtual-conference-176564/
-
🎉 OWASP is turning 25! 🎂
We're celebrating with a virtual party featuring awesome speakers, community stories, and more!
No travel. No hassle. Just log in, learn, connect, and celebrate 25 years of making software safer.
Join us! 🥳
https://owasp.glueup.com/event/owasp-25th-anniversary-virtual-conference-176564/
-
Security Tip: Limit the blast radius of leaked API keys. 🛡️
Rotation is vital, but scoping is your second line of defense. Apply granular permissions (Least Privilege) and restrict keys to specific IP addresses or CIDR blocks. This prevents an attacker from using a stolen key from their own infrastructure.
Stay informed on the latest vulnerabilities at https://cvedatabase.com
-
Security Tip: Reduce your container attack surface by using minimal base images. 🛡️ Standard OS images often include shells and utilities that attackers use for lateral movement. Switching to "distroless" or minimal Alpine images ensures only your application is present. Fewer binaries mean fewer vulnerabilities to track. Check for container-related vulnerabilities at: https://cvedatabase.com #InfoSec #AppSec #CloudNative
-
Introducing ZAP LLM Support:
https://www.zaproxy.org/blog/2026-08-07-zap-llm-support/
A new optional, opt-in add-on that lets you connect ZAP to an LLM of your choice.
#zaproxy #appsec -
Introducing ZAP LLM Support:
https://www.zaproxy.org/blog/2026-08-07-zap-llm-support/
A new optional, opt-in add-on that lets you connect ZAP to an LLM of your choice.
#zaproxy #appsec -
New by me: CybersecKyle Security How-To Series: Blue Team Fundamentals, Part 4 - Threat Modeling a Small Target
#Cybersecurity #InfoSec #ThreatModeling #AppSec #CybersecKyleHowTo
-
New by me: CybersecKyle Security How-To Series: Blue Team Fundamentals, Part 4 - Threat Modeling a Small Target
#Cybersecurity #InfoSec #ThreatModeling #AppSec #CybersecKyleHowTo
-
🤖 How the famed USENIX Security conf is managing a flood of papers in the AI era
📝 The 35th USENIX Secur...
📰 www.theregister.com - Articles
-
CVE-2026-48088 | CRITICAL in open-reception appointment-booking-software <1.0.4: Missing authorization on crypto key API lets attackers decrypt appointments & disrupt flows. Patch to 1.0.4 now. https://radar.offseq.com/threat/cve-2026-48088-cwe-862-missing-authorization-in-open-reception-appointment-booking-software-d1c4584f6afe2ecc
#OffSeq #CVE202648088 #Vuln #AppSec -
AI is rewriting code faster than humans can review it. Time to shift AppSec from “who wrote it” to “what it does.” https://jpmellojr.blogspot.com/2026/08/why-ai-coding-makes-zero-trust-appsec.html #AppSec #ZeroTrust #AISecurity #SupplyChainSecurity #DevSecOps #TrustModels
-
https://www.zaproxy.org/blog/2026-08-06-zap-updates-july-2026/ - a huge increase in the number of times ZAP was started, and we now recommend using the Client Spider instead of the AJAX Spider
#zaproxy #appsec -
https://www.zaproxy.org/blog/2026-08-06-zap-updates-july-2026/ - a huge increase in the number of times ZAP was started, and we now recommend using the Client Spider instead of the AJAX Spider
#zaproxy #appsec -
🔐 Secure applications are built, not bolted on.
At RELIANOID, our application security practices are aligned with the principles of ISO/IEC 27034, integrating security throughout the software lifecycle with continuous testing, vulnerability management, and secure-by-design development.
Because resilient infrastructure starts with secure applications.
📖 https://www.relianoid.com/security-compliances/relianoid-iso-iec-27034-compliance/
-
Security Tip: Don't ignore transitive dependencies. 🛡️
Your direct dependencies are just the tip of the iceberg. Vulnerabilities often lurk in the libraries your libraries depend on. Regularly audit your entire dependency tree using lockfile analysis and automated scanners. Understanding the full graph is key to supply chain security.
Research latest vulnerabilities at: https://cvedatabase.com
-
Security Tip: Don't let "orphaned" packages haunt your codebase. 🛡️ Libraries that are no longer maintained by their authors (abandonware) are a major security risk because they will never receive patches for newly discovered vulnerabilities. Regularly audit your dependency tree for projects with no recent commits or releases, and plan migrations to active alternatives. Stay informed on the latest library risks at https://cvedatabase.com #AppSec #InfoSec #SupplyChain
-
FlowiseAI Flowise <3.1.3 is affected by CRITICAL CVE-2026-70477 (code injection, CVSS 9.5). Exploitation via CSV Agent node allows arbitrary Python execution. Patch to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70477-cwe-94-improper-control-of-generation-of-code-code-injection-in-flowiseai-flowise-52ff32a90a84fd22 #OffSeq #Infosec #CVE #AppSec
-
CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. https://radar.offseq.com/threat/cve-2026-14175-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-bilin-software-and-caf423644ef42f8e #OffSeq #Vuln #AppSec
-
Security Tip: Automate your secret rotation. 🛡️ Storing secrets in a vault is only half the battle. If a key leaks, its value to an attacker is determined by its lifespan. Automated rotation ensures that even if a credential is compromised, it becomes useless quickly. Reduce the 'blast radius' of leaks by implementing short-lived tokens and automated lifecycle management. Resources: https://cvedatabase.com #InfoSec #CyberSecurity #AppSec #CloudSecurity
-
🦖 Life finds a way—and so do vulnerabilities.
Join us at #DEFCON34 to secure Apex Island! Use OWASP ASVS to find and patch flaws in a hands-on lab before the containment failure gets…toothy. https://luma.com/5geigcgf
LVCC, W4/1415 @owasp Community Village
#OWASP #AppSec -
You trust your dependencies? That’s the risk. From #Log4Shell to self-replicating worms, attacks don’t hit your code first — they hit your supply chain, often via packages.
@MohammadAliEN explains what to watch: https://javapro.io/2026/04/23/the-whispering-jar-java-security-lessons-hidden-in-a-fantasy-tale/
-
Никто не показывает, как стандарты ИБ связаны друг с другом поэтому пришлось собрать самому
OWASP, лаборатории, CVE, инструменты и патчи обычно живут в разных местах. Каждый раз собирать этот маршрут заново утомительно, поэтому и сделал RØØT — автономный полигон, который связывает всё в один процесс: понять → проверить → доказать → исправить → перепроверить
https://habr.com/ru/articles/1065380/
#кибербезопасность #AppSec #OWASP #CTF #API_Security #DevSecOps #CVE #CISA_KEV #open_source #root
-
The next one in the #peoplebehindosco series is Felix.
Hi @Gronner 👋
Felix is a software engineer with more than 10 years experience in the automotive and medical industry. Working at XITASO he focuses on building secure and safe systems. Besides that he provides trainings on security, safety, software architecture and Rust. To learn in and with a community he organises the SWEC and is a member of the iSAQB. He loves learning by exploring: building small embedded system or tools, mostly in Rust. In his spare time he enjoys playing pen & paper games, miniature figure painting and playing the drums.
His Tags: #AppSec, #Embedded, #Rust, #ThreatModeling
Thank you very much for your work as a volunteer and your support in organizing the Open Security conference. Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.